CVE-2022-22590
Published: 11 February 2022
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Priority
CVSS 3 base score: 8.8
Status
Package | Release | Status |
---|---|---|
qtwebkit-opensource-src Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Needs triage
|
|
impish |
Needs triage
|
|
jammy |
Needs triage
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Needs triage
|
|
qtwebkit-source Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Ignored
(end of standard support, was needs-triage)
|
|
webkit Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
webkit2gtk Launchpad, Ubuntu, Debian |
bionic |
Deferred
|
focal |
Released
(2.34.6-0ubuntu0.20.04.1)
|
|
impish |
Released
(2.34.6-0ubuntu0.21.10.1)
|
|
jammy |
Released
(2.35.3-1ubuntu1)
|
|
trusty |
Does not exist
|
|
upstream |
Released
(2.34.5,2.35.3)
|
|
xenial |
Deferred
|
|
webkitgtk Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Ignored
(end of standard support, was needs-triage)
|
|
wpewebkit Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Needs triage
|
|
impish |
Needs triage
|
|
jammy |
Needs triage
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
Notes
Author | Note |
---|---|
jdstrand | webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22590
- https://webkitgtk.org/security/WSA-2022-0002.html
- https://ubuntu.com/security/notices/USN-5306-1
- NVD
- Launchpad
- Debian